Quick start
Your first 15 minutes with ZoPanel: sign in, secure the admin login, give the panel a trusted domain, then create a package, an account and a website.
This guide takes you from a freshly installed server to a first hosted website. It assumes the installer has finished and printed the panel URL and admin password (see Install ZoPanel).
1. Sign in
- Open
https://YOUR-SERVER-IP:8888in your browser. - The panel uses a self-signed certificate until you set a panel domain, so the browser shows a warning. Continue to the site.
- Sign in with the username (
adminunless you chose another) and the password printed by the installer.
If you lost the password, reset it on the server:
zopanel ctl reset-password admin
2. Secure the administrator login
Open My account from the user menu at the top right.
Change the password
Under Change password, enter the current password and a new one of at least 8 characters, then click Update password.
Choose your own login name
Bots try admin first. Under Login name, enter a hard-to-guess name and click Change login name. Use the new name the next time you sign in.
Turn on two-factor authentication
- Under Two-factor authentication, click Enable 2FA.
- Scan the QR code with Google Authenticator, Authy, 1Password or a similar app.
- Enter the 6-digit code and click Verify & enable.
- Save the recovery codes somewhere safe. Each one signs you in once if you lose your phone, and they are shown only now.
If you ever lose both your phone and the recovery codes, an administrator with root access can run zopanel ctl disable-2fa USER.
To make 2FA mandatory for others, go to Settings → General → Require two-factor authentication and choose Administrators and resellers or Everyone.
3. Give the panel a domain and SSL
- Create an A record for a domain such as
panel.example.compointing to the server's IP. - Go to Settings → General.
- Fill in Administrator email (used for Let's Encrypt registration and notifications) and click Save. The certificate cannot be requested without it.
- In Panel domain & SSL, enter the domain in Panel domain.
- Click Issue certificate. A task requests a Let's Encrypt certificate.
- Open the panel at
https://panel.example.com:8888. The browser warning is gone, and the certificate renews automatically.
You can also limit who can open the panel in Restrict panel access; see Panel settings.
4. Create a package
A package is a resource plan that you assign to hosting accounts. The installer created one named Default (10 websites, 10 databases, 10 GB disk, 1 GB RAM, one CPU core). To create your own:
- Go to Packages and click New package.
- Enter a Package name, for example
Starter. - Set the limits: websites, databases, Disk (MB), CPU (%) (100 = one full core), RAM (MB), PHP memory_limit (MB), PHP workers and the others. For most limits
0means unlimited. - Turn SFTP on so the customer can upload files.
- Click Save.
See Packages and limits for every field.
5. Create a hosting account
Each account gets its own Linux user, home directory, PHP and resource limits.
- Go to Accounts and click New account.
- Enter a Username (3-16 lowercase letters and digits; it cannot be changed later), an Email and a Password. The password is used for both the panel and SFTP.
- Keep the Role as Customer. (Reseller needs a Pro license.)
- Choose the Package you created.
- Click Create. The panel shows the details to send to your customer, including the Panel URL.
The Free plan allows up to 3 hosting accounts, 10 websites and 10 databases on the server. See Licensing.
6. Add a website
- Point the domain's A record to the server's IP (do this first so SSL can be issued straight away).
- Go to Websites and click New website.
- Choose the Owner: the account you just created.
- Enter the Domain without
http://, for exampleexample.com. - Choose the Website type: WordPress, PHP, Laravel, HTML, Node / Proxy or Git deploy.
- Pick a PHP version and keep Free SSL (Let's Encrypt) on.
- Click Create website.
For WordPress, ZoPanel creates the database and installs WordPress for you. The full walkthrough, including DNS and file uploads, is in Your first website.
What to do next
- Install the optional components you need (mail, DNS, WAF and more) from Components: see Optional components.
- Set up alerts by Telegram, email or webhook in Settings → Alerts.
- Review the Security Center on the Security page and the suggestions on the Tuning page; many come with a one-click fix.
- Turn on Automatic updates in Settings → Updates: see Updating ZoPanel.